Updated version with modern debian, full docker build & docker-compose
Not too sure how to merge, but I do have a forked verison with most security issues removed & modern debian (9) with docker-compose and more recent 12.3 of postgresql.
https://github.com/munntjlx/jqplay
Hi @munntjlx, can you create a pull request to this repo? I'm happy to review your changes :).
Dumb question, I didn't fork, I copied and then modified. Most of my mods are simply new dockerfiles, and some 'npm audit fix' and a docker-compose.yml. I am not a programmer by trade, so please excuse lack of knowledge! I am a security person.
From: Owen Ou [email protected] Sent: Tuesday, July 21, 2020 17:21 To: jingweno/jqplay Cc: Munn, Thomas (RET-RDU); Mention Subject: Re: [jingweno/jqplay] Updated version with modern debian, full docker build & docker-compose (#102)
*** External email: use caution ***
Hi @munntjlxhttps://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fmunntjlx&data=02%7C01%7Cthomas.munn%40lexisnexis.com%7C8a2291ff4d2a483dbf7508d82dbbfe51%7C9274ee3f94254109a27f9fb15c10675d%7C0%7C0%7C637309632738902650&sdata=k5%2FkLiWhhv59jCva1u%2FBFPT1o%2Bf7f3c7psO8ETGOM%2F0%3D&reserved=0, can you create a pull request to this repo? I'm happy to review your changes :).
— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHubhttps://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fjingweno%2Fjqplay%2Fissues%2F102%23issuecomment-662112773&data=02%7C01%7Cthomas.munn%40lexisnexis.com%7C8a2291ff4d2a483dbf7508d82dbbfe51%7C9274ee3f94254109a27f9fb15c10675d%7C0%7C0%7C637309632738912646&sdata=Rnh9%2Bt3GdRyPjXPTe9IfmG1KcrWok6MyaXvGrqTUy2Q%3D&reserved=0, or unsubscribehttps://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FALVIUBYDMCMMVE2ZTWU7MZ3R4YBEPANCNFSM4PEBNPDA&data=02%7C01%7Cthomas.munn%40lexisnexis.com%7C8a2291ff4d2a483dbf7508d82dbbfe51%7C9274ee3f94254109a27f9fb15c10675d%7C0%7C0%7C637309632738912646&sdata=oOToaKioTNpDbvRTLXy%2BLFE%2BBcAJULKVej46kRFvqPY%3D&reserved=0.
I suspect the main culprits are going to be our package-lock and package.json. Not sure what 'npm audit fix -f' modifies.
You can create a patch, apply it on a fork of this repo and create a pull request. https://gist.github.com/cookrn/2140571 may help